First published: Fri Jun 22 2018(Updated: )
Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CivetWeb Project | <=1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12684 is a vulnerability in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 that allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file.
CVE-2018-12684 has a severity level of 7.1 (high).
The affected software of CVE-2018-12684 is CivetWeb through version 1.10.
To fix CVE-2018-12684, it is recommended to update CivetWeb to version 1.10 or apply the necessary patches provided by the vendor.
You can find more information about CVE-2018-12684 on the following references: [GitHub - CivetWeb Commit](https://github.com/civetweb/civetweb/commit/8fd069f6dedb064339f1091069ac96f3f8bdb552), [GitHub - CivetWeb Issue](https://github.com/civetweb/civetweb/issues/633)